CVE-2024-44112: SAP Oil %/ Gas
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow them to delete non-sensitive entries in a user data table. There is no effect on confidentiality or availability.
Affected products
- SAP Oil %/ Gas: version 600 only; version 602 only; version 603 only; version 604 only; version 605 only; version 606 only; …
Published 2024-09-10. Last modified 2026-06-17.